CVE-2026-44680
📛 CVE Title
(no title)
Description
MikroORM has SQL injection via runtime-controlled identifiers and JSON-path keys
Description (MITRE) cveawg.mitre.org
Pulled from cveawg.mitre.org/api/cve/CVE-2026-44680 on 2026-07-28. Shown when MITRE's text differs from the cvelistV5 mirror.
MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to @mikro-orm/knex 6.6.14 and @mikro-orm/sql 7.0.14, MikroORM's identifier-quoting helper (Platform.quoteIdentifier and the postgres/mssql overrides) and its JSON-path emitters (Platform.getSearchJsonPropertyKey, quoteJsonKey) did not properly escape characters that delimit the SQL identifier or string-literal context they emit into. When application code passes attacker-influenced strings to public ORM APIs that expect an identifier or a JSON-property filter, an attacker can break out of the quoted context and inject arbitrary SQL. This vulnerability is fixed in @mikro-orm/knex 6.6.14 and @mikro-orm/sql 7.0.14.
Overview
- State
- —
- Assigner (CNA)
- —
- CVSS severity
- high
- CVSS score
- 7.6 / 10
- CVSS vector
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L- Effective score
- 7.6 / 10 HIGH source: CNA overview
- CWE(s)
- —
- Reserved
- —
- Published
- —
- Last updated
- —
- Source
- https://www.tenable.com/cve/CVE-2026-44680
- Linked Threat
- CVE-2026-44680 — CVE-2026-44680
NVD / KEV / EPSS data refreshed 2026-05-24 23:55 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-31893
EUVD enrichment is queued; refresh the page in a few seconds.
Vendor references (0)
References embedded in the original CVE record by the assigning CNA.
None in the CVE record.
Web references (8)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://www.first.org/epss/ tenable:www.first.org
- https://github.com/mikro-orm/mikro-orm/pull/7654 tenable:github.com
- https://github.com/mikro-orm/mikro-orm/pull/7656 tenable:github.com
- https://github.com/mikro-orm/mikro-orm/pull/7657 tenable:github.com
- https://github.com/mikro-orm/mikro-orm/security/advisories/GHSA-cfw5-68c4-ffqp tenable:github.com
- https://github.com/mikro-orm/mikro-orm/pull/7653 tenable:github.com
- https://www.cve.org/CVERecord?id=CVE-2026-44680 tenable:www.cve.org
- https://nvd.nist.gov/vuln/detail/CVE-2026-44680 tenable:nvd.nist.gov
Remediations (10)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:community.ui.com
Published: May 21, 2026 Updated: May 22, 2026 Version: 1.1 Revision: 1.1 Summary 1 of 5 A malicious actor with access to the network and high privileges could exploit an Improper Input Validation vulnerability found in UniFi OS devices to execute a Command Injection. Affected Products: UniFi OS Server (Version 5.0.6 and earlier) Mitigation : Update your UniFi OS Server to Version 5.0.8 or later ...
2026-05-26 02:48 UTC -
web:docs.openclaw.ai
Migration checklist Use this checklist when you already know your old BlueBubbles config and want the shortest safe path: Verify imsg directly on the Mac that runs Messages.app (imsg chats, imsg history, imsg send, and imsg rpc --help). Copy behavior keys from channels.bluebubbles to channels.imessage: dmPolicy, allowFrom, groupPolicy, groupAllowFrom, groups, includeAttachments ...
2026-05-26 02:48 UTC -
web:finance.yahoo.com
An Ohio family is pushing back after their insurer says a repair is good enough. Here's why the suggested repair might violate the law.
2026-05-26 02:48 UTC -
web:hi.service-now.com
The Now Support portal is your launchpad to access self-help, get technical support, and manage your ServiceNow instances. Log in to manage upgrades, follow changes, view knowledge content, and more. Formerly HI portal.
2026-05-26 02:48 UTC -
web:onlyfans.com
OnlyFans is the social platform revolutionizing creator and fan connections. The site is inclusive of artists and content creators from all genres and allows them to monetize their content while developing authentic relationships with their fanbase.
2026-05-26 02:48 UTC -
web:wa.me
Hosted by WhatsApp 2026 © WhatsApp LLC Privacy & Terms
2026-05-26 02:48 UTC -
web:www.fda.gov
The Coronavirus Aid, Relief, and Economic Security Act (CARES Act) was signed into law on March 27, 2020 to aid response efforts and ease the economic impact of COVID-19.
2026-05-26 02:48 UTC -
web:www.forbes.com
False reports, including a fake CNN screenshot, are circulating on social media, claiming that a product based on honey can cure Alzheimer's disease.
2026-05-26 02:48 UTC -
web:www.virustotal.com
VirusTotal is a platform for scanning files and URLs for viruses, malware, and other threats using multiple antivirus engines.
2026-05-26 02:48 UTC -
web:www.wkyc.com
Cedar Point's Tony Clark says a fix is in the works to replace the shorter seat belts.
2026-05-26 02:48 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.